Trust · Security
Security evidence, without theater.
Insurf maintains a security program for its public site, private pilots, and internal operating systems. This page is a public summary; customers receive contract and evidence packets through approved diligence channels.
Controls
Operating posture.
The live program is intentionally conservative: high-risk paths fail closed until evidence exists.
- Access
- Founder/admin access is MFA-oriented and reviewed for production paths; Vanta now monitors Google Workspace and GitHub evidence.
- Code
- GitHub is connected to Vanta for repository and Dependabot evidence. Branch protection enforcement remains an open remediation item until GitHub settings are updated.
- Cloud
- AWS is the intended covered cloud boundary for S3, KMS, Textract, and logging. Vanta AWS monitoring awaits the CloudFormation-created VantaAuditorRoleArn.
- Vendors
- The PHI path is limited to AWS, Vercel, Neon, and OpenAI unless a signed customer agreement authorizes more.
Boundaries
What is not claimed.
- Insurf does not claim SOC 2 certification or a completed SOC 2 report.
- Insurf does not claim HIPAA certification; HIPAA readiness depends on BAAs, policies, and launch controls.
- Public demos use synthetic or redacted material, not production PHI.
- Any vulnerability disclosure should avoid accessing customer data, modifying data, or disrupting service.